Executive brief
The Ajax Load More - Filters plugin for WordPress, which allows website owners to create advanced search and filtering systems for their content, is vulnerable to a security flaw. An attacker can inject malicious scripts into the website's pages without needing to log in. If successful, these scripts will run in the browsers of any visitors who view the affected pages, potentially leading to unauthorized actions or data theft.
Technical details
The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'taxonomy_include_children' parameter. The vulnerability exists in all versions up to and including 3.4.1. An unauthenticated attacker can exploit this by sending a specially crafted request to inject arbitrary web scripts into the database. These scripts are subsequently executed in the browser of any user who accesses the affected page. The attack vector is network-based, requires no special privileges, and no user interaction is needed for the initial injection.
Affected products
- Connekt Media Ajax Load More - Filters 0 - 3.4.1
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory